OpenClaw records
577 published records for vendor openclaw.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 10
- With a fix record
- 99.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-863 Incorrect Authorization92
- CWE-862 Missing Authorization42
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')32
- CWE-184 Incomplete List of Disallowed Inputs31
- CWE-918 Server-Side Request Forgery (SSRF)31
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')24
The weakness classes this vendor ships most often: where to look.
CWEAll records
577 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2026-25253Proof of concept | OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket conneopenclaw · openclaw · CWE-669 | High8.8 | — | 24.4% | Feb 1, 2026 |
39Monitor | CVE-2026-30741Proof of concept | A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Siopenclaw · openclaw · CWE-94 | Critical9.8 | — | 1.2% | Mar 11, 2026 |
37Monitor | CVE-2026-24763No exploit | Authenticated Command Injection in OpenClaw Docker Execution via PATH Environment Variableopenclaw · openclaw · CWE-78 | High8.8 | — | 5.3% | Feb 2, 2026 |
37Monitor | CVE-2026-32917No exploit | OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCPopenclaw · openclaw · CWE-78 | Critical9.2 | — | 3.2% | Mar 31, 2026 |
37Monitor | CVE-2026-28474No exploit | OpenClaw Nextcloud Talk < 2026.2.6 - Allowlist Bypass via actor.name Display Name Spoofingopenclaw · openclaw · CWE-863 | Critical9.3 | — | 0.9% | Mar 5, 2026 |
37Monitor | CVE-2026-28466Proof of concept | OpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval Bypassopenclaw · openclaw · CWE-863 | Critical9.4 | — | 0.7% | Mar 5, 2026 |
37Monitor | CVE-2026-32922No exploit | OpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotateopenclaw · openclaw · CWE-266 | Critical9.4 | — | 0.7% | Mar 29, 2026 |
37Monitor | CVE-2026-32987No exploit | OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairingopenclaw · openclaw · CWE-294 | Critical9.3 | — | 0.6% | Mar 29, 2026 |
37Monitor | CVE-2026-22172No exploit | OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connectionsopenclaw · openclaw · CWE-862 | Critical9.4 | — | 0.6% | Mar 20, 2026 |
37Monitor | CVE-2026-33579Proof of concept | OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approvalopenclaw · openclaw · CWE-863 | Critical9.4 | — | 0.5% | Mar 31, 2026 |
37Monitor | CVE-2026-32038No exploit | OpenClaw - Sandbox Network Isolation Bypass via docker.network=container Parameteropenclaw · openclaw · CWE-284 | Critical9.3 | — | 0.5% | Mar 19, 2026 |
37Monitor | CVE-2026-32978No exploit | OpenClaw < 2026.3.11 - Approval Bypass via Unrecognized Script Runnersopenclaw · openclaw · CWE-863 | Critical9.4 | — | 0.3% | Mar 29, 2026 |
37Monitor | CVE-2026-43534No exploit | OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Eventsopenclaw · openclaw · CWE-345 | Critical9.3 | — | 0.3% | May 5, 2026 |
37Monitor | CVE-2026-32915No exploit | OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Subagent Control Surfaceopenclaw · openclaw · CWE-863 | Critical9.3 | — | 0.2% | Mar 29, 2026 |
36Monitor | CVE-2026-44109No exploit | OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validationopenclaw · openclaw · CWE-1188 | Critical9.2 | — | 1.1% | May 6, 2026 |
36Monitor | CVE-2026-28446No exploit | OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matchingopenclaw · openclaw · CWE-303 | Critical9.2 | — | 1.0% | Mar 5, 2026 |
36Monitor | CVE-2026-28470No exploit | OpenClaw < 2026.2.2 - Exec Allowlist Bypass via Command Substitution in Double Quotesopenclaw · openclaw · CWE-78 | Critical9.2 | — | 0.9% | Mar 5, 2026 |
36Monitor | CVE-2026-28391No exploit | OpenClaw < 2026.2.2 - Command Injection via cmd.exe Parsing Bypass in Allowlist Enforcementopenclaw · openclaw · CWE-78 | Critical9.2 | — | 0.9% | Mar 5, 2026 |
36Monitor | CVE-2026-43585No exploit | OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolutionopenclaw · openclaw · CWE-672 | Critical9.2 | — | 0.8% | May 6, 2026 |
36Monitor | CVE-2026-43575No exploit | OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper Routeopenclaw · openclaw · CWE-862 | Critical9.2 | — | 0.8% | May 6, 2026 |
36Monitor | CVE-2026-43566No exploit | OpenClaw 2026.4.7 < 2026.4.14 - Privilege Escalation via Untrusted Webhook Wake Eventsopenclaw · openclaw · CWE-184 | Critical9.1 | — | 0.7% | May 5, 2026 |
36Monitor | CVE-2026-28472No exploit | OpenClaw < 2026.2.2 - Device Identity Check Bypass in Gateway WebSocket Connect Handshakeopenclaw · openclaw · CWE-306 | Critical9.2 | — | 0.7% | Mar 5, 2026 |
36Monitor | CVE-2026-32916No exploit | OpenClaw 2026.3.7 < 2026.3.11 - Authorization Bypass in Plugin Subagent Routes via Synthetic Admin Scopesopenclaw · openclaw · CWE-266 | Critical9.2 | — | 0.6% | Mar 31, 2026 |
36Monitor | CVE-2026-41386No exploit | OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codesopenclaw · openclaw · CWE-648 | Critical9.1 | — | 0.6% | Apr 28, 2026 |
36Monitor | CVE-2026-41329No exploit | OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalationopenclaw · openclaw · CWE-648 | Critical9.0 | — | 0.5% | Apr 20, 2026 |
- CVE-2026-2525342Plan
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket conne
HighCVSS 8.8Proof of conceptEPSS 24%openclaw · openclawFeb 1, 2026
- CVE-2026-3074139Monitor
A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Si
CriticalCVSS 9.8Proof of conceptEPSS 1%openclaw · openclawMar 11, 2026
- CVE-2026-2476337Monitor
Authenticated Command Injection in OpenClaw Docker Execution via PATH Environment Variable
HighCVSS 8.8No exploitEPSS 5%openclaw · openclawFeb 2, 2026
- CVE-2026-3291737Monitor
OpenClaw < 2026.3.13 - Remote Command Injection via Unsanitized iMessage Attachment Paths in SCP
CriticalCVSS 9.2No exploitEPSS 3%openclaw · openclawMar 31, 2026
- CVE-2026-2847437Monitor
OpenClaw Nextcloud Talk < 2026.2.6 - Allowlist Bypass via actor.name Display Name Spoofing
CriticalCVSS 9.3No exploitEPSS 1%openclaw · openclawMar 5, 2026
- CVE-2026-2846637Monitor
OpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval Bypass
CriticalCVSS 9.4Proof of conceptEPSS 1%openclaw · openclawMar 5, 2026
- CVE-2026-3292237Monitor
OpenClaw < 2026.3.11 - Privilege Escalation via Unvalidated Scope in device.token.rotate
CriticalCVSS 9.4No exploitEPSS 1%openclaw · openclawMar 29, 2026
- CVE-2026-3298737Monitor
OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing
CriticalCVSS 9.3No exploitEPSS 1%openclaw · openclawMar 29, 2026
- CVE-2026-2217237Monitor
OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections
CriticalCVSS 9.4No exploitEPSS 1%openclaw · openclawMar 20, 2026
- CVE-2026-3357937Monitor
OpenClaw < 2026.3.28 - Privilege Escalation via Missing Caller Scope Validation in Device Pair Approval
CriticalCVSS 9.4Proof of conceptEPSS 1%openclaw · openclawMar 31, 2026
- CVE-2026-3203837Monitor
OpenClaw - Sandbox Network Isolation Bypass via docker.network=container Parameter
CriticalCVSS 9.3No exploitEPSS 0%openclaw · openclawMar 19, 2026
- CVE-2026-3297837Monitor
OpenClaw < 2026.3.11 - Approval Bypass via Unrecognized Script Runners
CriticalCVSS 9.4No exploitEPSS 0%openclaw · openclawMar 29, 2026
- CVE-2026-4353437Monitor
OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events
CriticalCVSS 9.3No exploitEPSS 0%openclaw · openclawMay 5, 2026
- CVE-2026-3291537Monitor
OpenClaw < 2026.3.11 - Sandbox Boundary Bypass via Subagent Control Surface
CriticalCVSS 9.3No exploitEPSS 0%openclaw · openclawMar 29, 2026
- CVE-2026-4410936Monitor
OpenClaw < 2026.4.15 - Authentication Bypass in Feishu Webhook and Card-Action Validation
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMay 6, 2026
- CVE-2026-2844636Monitor
OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMar 5, 2026
- CVE-2026-2847036Monitor
OpenClaw < 2026.2.2 - Exec Allowlist Bypass via Command Substitution in Double Quotes
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMar 5, 2026
- CVE-2026-2839136Monitor
OpenClaw < 2026.2.2 - Command Injection via cmd.exe Parsing Bypass in Allowlist Enforcement
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMar 5, 2026
- CVE-2026-4358536Monitor
OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMay 6, 2026
- CVE-2026-4357536Monitor
OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper Route
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMay 6, 2026
- CVE-2026-4356636Monitor
OpenClaw 2026.4.7 < 2026.4.14 - Privilege Escalation via Untrusted Webhook Wake Events
CriticalCVSS 9.1No exploitEPSS 1%openclaw · openclawMay 5, 2026
- CVE-2026-2847236Monitor
OpenClaw < 2026.2.2 - Device Identity Check Bypass in Gateway WebSocket Connect Handshake
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMar 5, 2026
- CVE-2026-3291636Monitor
OpenClaw 2026.3.7 < 2026.3.11 - Authorization Bypass in Plugin Subagent Routes via Synthetic Admin Scopes
CriticalCVSS 9.2No exploitEPSS 1%openclaw · openclawMar 31, 2026
- CVE-2026-4138636Monitor
OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
CriticalCVSS 9.1No exploitEPSS 1%openclaw · openclawApr 28, 2026
- CVE-2026-4132936Monitor
OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
CriticalCVSS 9.0No exploitEPSS 1%openclaw · openclawApr 20, 2026